ShinyHunters Claims Unprecedented FBI Hack, 2–3 TB of Data Allegedly Exfiltrated
ShinyHunters claimed that it breached the Federal Bureau of Investigation (FBI) and exfiltrated roughly 2 to 3 TB of data. The claim is significant, but there is an important qualification: as of the latest reporting, the FBI has not publicly confirmed the claimed compromise or the scope of the alleged data theft.
According to reporting published by The Register on September 22:
- Initial compromise: ShinyHunters says it exploited a previously unknown vulnerability in Oracle PeopleSoft exposed through the FBI's jobs website. The vulnerability allegedly provided remote code execution (RCE) on the affected servers.
- Website defacement: After obtaining access, the attackers reportedly defaced the FBI recruitment site with a message claiming the site had been seized by ShinyHunters. At the time of The Register's reporting, the FBI jobs site subsequently displayed a maintenance message.
- Lateral movement: The group claims it was able to move beyond the compromised recruitment infrastructure into FBI-managed systems hosted within AWS GovCloud. This is currently an attacker claim, not an independently verified finding.
- Large-scale exfiltration: ShinyHunters claims it downloaded approximately 2 to 3 TB of information concerning current employees, former employees and FBI job applicants.
- The group additionally claims that compromised FBI services included human resources, MedLink and Criminal Justice Information Services (CJIS). Those claims have not yet been independently confirmed.
Current assessment
Item | Current status |
Threat actor | ShinyHunters claims responsibility |
Target | FBI |
Public disclosure | September 22, 2026 |
Claimed entry point | FBI jobs/recruitment infrastructure |
Technology | Oracle PeopleSoft |
Alleged technique | Pre-authentication RCE / zero-day |
Alleged lateral movement | AWS GovCloud |
Claimed theft | ~2-3 TB |
Claimed victims | Current/former FBI personnel + applicants |
FBI confirmation | Not confirmed in the reporting available |
Confidence in full attacker claims | Unverified / developing |
An unusual motive
There's another interesting aspect to this incident.
ShinyHunters told The Register that the operation was not financially motivated and that it was not currently seeking a traditional extortion payment from the FBI. Instead, the group says it wants the FBI to retract or correct statements contained in an earlier FBI advisory about ShinyHunters.
That dispute relates to an FBI advisory issued on May 15, 2026.
In that advisory, the FBI described ShinyHunters as a cybercriminal group specializing in large-scale data breaches and extortion. The bureau warned that actors using the ShinyHunters identity employ pressure tactics against victims and may make real or exaggerated claims concerning stolen sensitive information.
The FBI consequently advises treating claims from ShinyHunters with caution and recommends awaiting authoritative confirmation about what data was actually compromised following an intrusion.
That warning is particularly relevant here.
Why I would classify this as "Critical, but unconfirmed"
The 2-3 TB figure should not yet be presented as established fact.
There's a major difference between confirming:
FBIJobs infrastructure was compromisedand confirming:
ShinyHunters penetrated FBI GovCloud infrastructure and extracted several terabytes containing data on the FBI workforce and CJIS systems.The second claim would represent a substantially greater security incident.
As of the latest reporting I found, The Register specifically states that the FBI had not responded to its request for comment. Oracle and AWS likewise had not responded to its questions concerning the claimed PeopleSoft vulnerability and alleged data access.
Therefore, for a threat-intelligence report I'd currently label this:
Severity: Critical
Confidence: Medium-Low / Developing
Attribution: ShinyHunters self-attribution
Data theft: Claimed, not yet independently verified
Defender implications
Gary, there's one part of this story I'd pay particular attention to given your systems/security role: PeopleSoft exposure.
If the reported intrusion vector proves accurate, the defensive lesson isn't limited to federal agencies. Internet-facing ERP, HR and applicant-tracking systems can hold extremely sensitive identities while simultaneously having connections into internal enterprise environments.
Organizations operating PeopleSoft should immediately prioritize:
1. Identify exposed PeopleSoft infrastructure
Inventory:
- Internet-facing PeopleSoft systems
- PeopleTools components
- Reverse proxies publishing PeopleSoft
- Applicant/recruitment portals
- HR integrations
- SSO connections
- Service accounts
- Cloud workloads reachable from these servers
2. Treat the application server as potentially compromised
Don't limit hunting to web logs.
Review for unusual:
PeopleSoft -> PowerShellPeopleSoft -> cmd.exePeopleSoft -> scripting engineWeb server -> outbound connectionApplication server -> unusual AWS/Azure accessApplication identity -> HR/database accessApplication server -> SMB/RDP/WinRMIf an Internet-facing application can execute code and its identity has access to downstream resources, exploitation can turn an application vulnerability into an identity and lateral-movement event.
Watch for secondary identity attacks
If personnel or applicant information was actually taken, the stolen information could potentially make subsequent spear-phishing or impersonation attacks considerably more convincing.
The FBI itself has previously warned that stolen sensitive enterprise information can be reused to construct sophisticated spear-phishing and impersonation campaigns.
That means defenders shouldn't consider this solely a PeopleSoft vulnerability issue. It potentially becomes an:
ERP → Identity → Cloud → Data exfiltration
incident chain.
One particularly important detail
This also appears to be different from the Florida DAVID incident involving ShinyHunters earlier this month.
In that case, Florida authorities confirmed unauthorized access to the state's DAVID driver database associated with compromised credentials belonging to a police department user. ShinyHunters had claimed access to multiple accounts, including an FBI agent's account, but that was an attack against Florida's driver database rather than a compromise of FBI infrastructure itself.
The September 22 FBI claim is therefore a separate and potentially much more significant incident.
.png)
Comments
Post a Comment